DeleteNetworkAcl
DeleteNetworkAcl
Event
Deletes a custom network ACL only when it is not associated with any subnets. The default ACL cannot be deleted. This operation does not leave a subnet without an ACL; examine earlier association changes to determine any change in active filtering.
Security Context
An attacker may delete an unused former ACL after changing subnet protection, but routine cleanup is also common. Deletion of an unassociated ACL alone does not establish weaker filtering. The cloud-firewall mapping is contextual to the broader impairment sequence.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteNetworkAcl. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.networkAclId | Deleted ACL; recover its former rules and associations. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect errors or dry-run results; verify whether the ACL existed and was nondefault.
- Recover previous subnet associations and look for ReplaceNetworkAclAssociation calls.
- Compare the replacement ACL rules with the prior rules; determine when active protection actually changed.
- Correlate with DeleteNetworkAclEntry and verify current subnet protection.
Sample Event
Synthetic scenario. Draco requests deletion of a fictional custom ACL assumed to be unassociated. This sample cannot show removal of a subnet’s last ACL or prove traffic became allowed. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:27:48Z", "eventSource": "ec2.amazonaws.com", "eventName": "DeleteNetworkAcl", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "networkAclId": "acl-0abcdef0123456789" }, "responseElements": { "requestId": "90000000-0000-4000-8000-000011110000", "_return": true }, "requestID": "90000000-0000-4000-8000-000011110000", "eventID": "90000000-0000-4000-8000-000011110001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.